Analytics BIOC
Informational
✕
Unusual exec into a Kubernetes Pod
An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Container Administration Command (T1609)
Detector tags: Kubernetes - API
Attacker's goals:
Execute commands within the Kubernetes Pod. Access any resource the Kubernetes Pod has access to.
Investigative actions:
Check the identity's role designation in the organization. Inspect for any additional suspicious activities inside the Kubernetes Pod.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
5 variations:
- Failed exec attempt into a Kubernetes Pod Informational
- First time execution into Kubernetes Pod at the cluster-level Medium (parent: Informational)
- Identity executed into Kubernetes Pod for the first time Low (parent: Informational)
- Identity executed into a Kubernetes namespace for the first time Low (parent: Informational)
- Identity executed into a Kubernetes Pod for the first time Low (parent: Informational)